Intel

AIKIDO-2026-859281

cxf-rt-transports-jms is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-50632 Published Today

81

High Risk

This Affects:

JAVAcxf-rt-transports-jms
0.0.0 - 4.1.6
Fixed in 4.1.7
4.2.0 - 4.2.1
Fixed in 4.2.2
Are you affected? Scan for Free

TL;DR

A further incomplete fix for CVE-2026-44417 leaves additional JNDI validation gaps in Apache CXF JMS configuration handling. If untrusted users can supply JMS or JNDI settings, attacker-controlled environment properties or URL-style JNDI names can still reach unsafe lookup paths and may lead to remote code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if untrusted users are allowed to configure JMS for Apache CXF.

Background info

cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 0.0.0 - 4.1.6 and 4.2.0 - 4.2.1.

How to fix this

Upgrade the org.apache.cxf:cxf-rt-transports-jms library to the patch version.